Re: Promiscuous Mode



On Thu, Mar 20, 2008 at 12:51 AM, Simon Templar
<73696d6f6e74656d706c617200@xxxxxxxxxxxxxx> wrote:
I have a question concerning "Promiscuous Mode", I know what it is,
but I would like to know exactly what is happening behind the scenes
when I change my NIC to this mode

When promiscuous mode is disabled your NIC filters anything that isn't
destined for its MAC address.

Essentially enabling promiscuous mode allows ALL packets in regardless
of what their Destination MAC address is.

It won't make any difference on a switched network as you won't see
packets not destined for your MAC address anyway (Unless they're
broadcast packets)

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • Re: Firewall and IDS, (the second way).
    ... There is another way of detecting an interface in promiscuous mode.. ... The basic idea is to spoof the destination mac address of the ip your ... > the network in question. ...
    (Vuln-Dev)
  • Re: Problem with etherchannel between 2 3550 FXs
    ... > and destination MAC addresses. ... > of the final bits of each of the source and destination ... > You get to choose which logical operation you want, ... > provided you aren't fragmenting packets; ...
    (comp.dcom.sys.cisco)
  • Re: ARP requests on my net?
    ... MAC should be dumped. ... should dump packets not destined for its MAC. ... Or does IP need the MAC of the destination ... needs to send to the router via ethernet so it ARP's the ...
    (Fedora)
  • Re: TCPReplay problem
    ... You can use tcpreplay to send packets to another machine. ... you can change the source and destination IP addresses for all packets with the '-e' flag. ... However, you should also change the layer 2 source and destination MAC, which can be done with the '-I' and '-k' flags. ...
    (Pen-Test)
  • Re: em0, VLAN and bpf(?) trouble w/RELENG_5
    ... >> command on Catalyst don't show the MAC. ... Can it happen that way that bpf (or maybe it's promiscuous mode?) just ... "eats" all packets without returning them back into network stack? ... local Ukrainian FreeBSD people suggested trying -p switch to trafshow - ...
    (freebsd-current)